From 4868bfcaf76bf8101e473394e5cc9adf569e8455 Mon Sep 17 00:00:00 2001 From: Gidon Studinski Date: Tue, 19 Nov 2019 18:15:35 +0200 Subject: [PATCH] wigig_sensing: enforce data read in multiple of burst size In case user space application requests for data size which is not a multiple of the burst size and there is enough data in the drivers internal buffer, a partial burst may be read by the application, which may cause loss of burst boundary. This patch fixes the above. In case the application supplies a buffer which is smaller than the burst size, an error is returned to the application. Change-Id: I5233476d99937dd1a13ceaec625588414a1dc04a Signed-off-by: Gidon Studinski Signed-off-by: Alexei Avshalom Lazar --- drivers/misc/wigig_sensing.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/drivers/misc/wigig_sensing.c b/drivers/misc/wigig_sensing.c index a7751e0afef4..739747e0ff04 100644 --- a/drivers/misc/wigig_sensing.c +++ b/drivers/misc/wigig_sensing.c @@ -711,6 +711,12 @@ static ssize_t wigig_sensing_read(struct file *filp, char __user *buf, if (ctx->stm.change_mode_in_progress) return -EINVAL; + /* Read buffer too small */ + if (count < ctx->stm.burst_size) { + pr_err("Read buffer must be larger than burst size\n"); + return -EINVAL; + } + /* No data in the buffer */ while (circ_cnt(&d->b, d->size_bytes) == 0) { if (filp->f_flags & O_NONBLOCK) @@ -720,11 +726,11 @@ static ssize_t wigig_sensing_read(struct file *filp, char __user *buf, circ_cnt(&d->b, d->size_bytes) != 0)) return -ERESTARTSYS; } - if (mutex_lock_interruptible(&d->lock)) return -ERESTARTSYS; copy_size = min_t(u32, circ_cnt(&d->b, d->size_bytes), count); + copy_size -= copy_size % ctx->stm.burst_size; size_to_end = circ_cnt_to_end(&d->b, d->size_bytes); tail = d->b.tail; pr_debug("copy_size=%u, size_to_end=%u, head=%u, tail=%u\n",